I would like to make a wager on this law being ignored the first time Samsung or another chaebol violates it and is facing a fine equal to 10% of revenue. I can almost guarantee it, it’s a high enough fine to turn some low-margin businesses from profitable to unprofitable for the year and there’s no such thing as a secure computer system. The only way to guarantee compliance is to not store any data which isn’t exactly reasonable for some business models.
> there’s no such thing as a secure computer system
Where is your source for this? It is entirely possible to make a secure computer system, though it does require effort. The article specifically mentions "up to" 10% and the fines applying to companies leaking data on purpose or through negligence. I doubt the fines will be nearly as high for a company that tries to secure a system (and thus prevents more leaks) rather than a company that does not try to secure a system (assuming that leaks will occur), if the same breach happens.
Computers are deterministic (excluding cases where practically impossible cosmic ray events occur), so while we have the power to ensure system security, we should ensure system security. Heck, even just encrypting consumer information and protecting just the keys to this data would already decrease the effectiveness of many data breaches.
It is not possible to make a secure computer system that is also usable. There is ultimately no way to avoid the tradeoff between convenience and security.
You can make a system "more" secure than other systems, but you cannot make it truly secure.
Wow! :O Finally, a legislator with enough balls to put up something that _might_ (just might) make corporations _actually_ care about security and privacy! I can't wait for this to start being adopted in other countries. It's about time!
The US is probably among the countries, where the lobbying against such a law or policy would be very severe, because multiple of their tech giants are built on the foundation of abusing people and considering fines to be cost of business.
You can just do what my university did, hire a small shell firm with 3 employees to hold all your data, and when it got hacked they just went bankrupt and we switched to a new firm with similar form or function.
Perfect isn’t required. The bar is “gross negligence”. Perfect is impossible, but proper compliance procedures, proper process, and a commitment to following industry best practice will always see you on the right side of the negligence bar, even if something slipped through the net.
It’s the difference between being a professional and an amateur (or worse, a ‘cowboy’).
The bar is: do you have effective compliance in place? And are you audited? (ISO27001 [1] or similar).
If you are hacked and you are seen have not given a shit about compliance, or independent penetration tests, or proper documentation of process, with good internal controls enforcing your processes. Then you’re almost certainly vulnerable to a negligence claim.
However, if you have all that in place, and somehow something slipped through the net. And once aware you put in new controls to make sure it doesn’t happen again, then you’re very unlikely to have the book thrown at you.
You may still get a fine, but it would be much reduced.
It’s not hard to do this. Yes, compliance can be overdone, so you need key stakeholders to make sure it doesn’t turn into jobsworth heaven; but the actual implementation isn’t hard to do, and if done well, will improve the processes within the business.
It’s very much like an insurance policy. It has some ongoing cost, but it saves you from the one big cost.
Followed by deleting data once you've used it for its stated purpose.
Personal data needs to be much more of a liability than it currently is for anything to change. Business will respond when the bottom line is affected.
that's the odd thing: we simply don't ask whether there's an alternative.
for instance, how many companies (including universities) store their own cash on prem? what if we treated PII like cash? limit amount and time kept outside the data "bank" (which would be a third party specialized for security and authenticating access).
Funny you say that without even knowing the school’s use case for the data. And most certainly in the abstract, companies have even less reason to collect PII than they are currently doing.
Problem is that most breaches are social engineering attacks where employees or customers are phished for their credentials or even to approve/install some malicious code. It's very hard for businesses to defend against this.
They can try:
* various education campaigns
* force users/customers to adopt passkeys or other phishing resistant mfa
* add various alarms and alerts for unusual activity, resulting in lockout
The problem is that even after adopting all of the above, it's still not too hard to breach virtually all companies, and there is massive user opposition to the last two.
How much to care is reasonable? Do you live in a windowless underground security bunker? Should most businesses be held to that standard?
Lets say these are paper records, behind a locked door, with a security guard that they check id for it. If someone then breaks in at night time, cuts the cameras and knocks out the security guard and steals a filing cabinet, should that university then be fined 10% of revenue, which could mean the entire university shuts down? We have to remember who is the original criminal here.
Parent isn't talking about shareholders or ownership, but full delegation of a process to a contracting company.
Calling "shell company" makes it sound like the University is the shareholder, but that's usually not what's happening IMHO. In general the entities are clearly defined and nothing crosses the client/contractor frame, the university just happens to be the sole client and the contractor will have the uni pay for their whole operation.
If they see people doing exactly what was described to avoid fines I think they will amend the law to explicitly allow piercing the veil. Just like for directors
>You can just do what my university did, hire a small shell firm with 3 employees to hold all your data
except you can't in South Korea because PIPA (their data privacy/compliance framework) is as strict if not stricter than GDPR and comes with criminal liability in case you violate consent rules, so you can't just send other people's data to some third party shell company either
why do people always make these completely generic comments as if they've just on the toilet figured out the one simple trick every data framework covered over a decade ago
The hope is they levy few fines. When you want to make money you set the fines such that they are "a cost of doing business". Most often you don't even call them fines, you call them a permit/license fee (though fines are also common). When you want to prevent a behavior you make the costs high enough that it is worth the effort to not pay them in the first place.
(I'm assuming here that 10% is high enough that nobody would call it a cost of doing business - I could be wrong)
It's childish of me I know, but if this actually goes through I will feel a twinge of delight at the refutation of all the HN commenters who have argued that such enforcement is unrealistic.
Assuming global adoption, this would also have the side effect of increasing bug bounty payouts. Consider the recent OpenAI compromise: an attack RCE, an SSO configuration flaw, and subsequent employee account takeover, for a mere $6500 bounty for a trillion-dollar company.
Tying the fine to intent or gross negligence doesn't work for me, as a customer doesn't care why, they only care that the harm happened. Doesn't matter to me if you train everyone really well and one guy forgot his training just one time, or if you don't train at all.
I'm thinking:
(The following example is in "American" terms, I assume some other countries have similar ideas as SSN though)
- Name and address or name and phone number leak: $100 per customer affected.
- Email: $50 per customer affected, or $100 if tied to any other data.
- Social Security numbers: $2000 per customer affected
- Unsalted or plaintext passwords: $500 per customer affected.
- Cap is the greater of 200% of annual EBITDA, or 20% of revenue
Money goes to the government to be distributed DIRECTLY (tax-free) to the affected users.
This might bankrupt a couple of companies in particularly bad breaches, while companies are still getting used to it. Good! I hope it does and that business textbooks highlight those disasters, the way they do the Enron collapse.
My goals for this system are for businesses to properly price in the risk of holding (or even momentarily touching) sensitive data. SSNs, for instance should already (in a sane world) be radioactive for any business to even CONSIDER touching. To the extent any business feels the need to collect or hold it, frankly I'd say, think again. Credit reporting agencies are the worst offenders (and under my rules Equifax would already be gone), as they maintain databases with that as primary key, and force all their customers to deal in that key, instead of taking advantage of some 1990s technology like one-way hashing, or better yet, coming up with their own identifiers that could be replaced responsibly in the case of breaches.
SSN should be 1MM+. It is a password to your national identity that can be used to steal your identity and effectively cannot be revoked once leaked. It is a permanent grievous injury to someone to leak it.
The irony is that corporations get a higher discount the more people they affect. Damaging 10,000,000 people should cost you more than 10,000,000 times the cost of damaging one, not less. It should be ruinous to cause damage at this scale.
This is exactly what we need in the West! I have a strong suspicion that nobody here actually cares about security or customer data being spilled into the streets.
Security costs money and as long as there aren't any penalties for negligence management will make the calculation to prioritize increased profitability over securing company data.
And what about the governments like Berlin for example? Massive data breach, and guess what happens? Nothing to those who are responsible for the breach.
So even though this is Korea, it is modern hypocrisy. Companies have to comply to more and more complicated regulation, while those who govern the states get a free pass.
If the Berlin incident remotely had happened to any private company - hell would have been loose.
Berlin reduced the IT budget especially regarding maintenance and security massively over the years. In fact, what came to light - CCC talk as a reference besides others - sounds so embarrassing, that all companies should get a bonus payment whenever they get hacked.
Basing it on revenue is sensible, since the goal is to make it hurt. But that would argue for a higher fraction. But the main thing is to introduce an incentive to take security more seriously.
67 comments
[ 0.25 ms ] story [ 19.4 ms ] threadWhere is your source for this? It is entirely possible to make a secure computer system, though it does require effort. The article specifically mentions "up to" 10% and the fines applying to companies leaking data on purpose or through negligence. I doubt the fines will be nearly as high for a company that tries to secure a system (and thus prevents more leaks) rather than a company that does not try to secure a system (assuming that leaks will occur), if the same breach happens.
Computers are deterministic (excluding cases where practically impossible cosmic ray events occur), so while we have the power to ensure system security, we should ensure system security. Heck, even just encrypting consumer information and protecting just the keys to this data would already decrease the effectiveness of many data breaches.
I have my doubts. Certainly no one has ever built such a system.
It is exceptionally difficult to ensure that software is free of bugs, and most applications are too complex to formally verify.
You can’t. You don’t need source for that, just common sense.
Exploits are discovered every day, bugs happen, bad actors.
You can do the best system, shit still happen.
BTW you want a source ? Remember when the freaking CIA data got leaked ? Edward Snowden, ring a bell ?
If the cia couldn’t prevent it, I bet you can’t.
You can make a system "more" secure than other systems, but you cannot make it truly secure.
* Before Tax Revenue
* If the company is owned by another company, the revenue is the total of all companies owned by the highest level parent.
* Includes Worldwide Revenue
* Includes companies based in all other Countries.
I would have went for 20%, but if he above applies I wish the US would do the same.
I might suggest a construct like this too.
What do you think how much it cost to do it perfect?
It’s the difference between being a professional and an amateur (or worse, a ‘cowboy’).
If you are hacked and you are seen have not given a shit about compliance, or independent penetration tests, or proper documentation of process, with good internal controls enforcing your processes. Then you’re almost certainly vulnerable to a negligence claim.
However, if you have all that in place, and somehow something slipped through the net. And once aware you put in new controls to make sure it doesn’t happen again, then you’re very unlikely to have the book thrown at you.
You may still get a fine, but it would be much reduced.
It’s not hard to do this. Yes, compliance can be overdone, so you need key stakeholders to make sure it doesn’t turn into jobsworth heaven; but the actual implementation isn’t hard to do, and if done well, will improve the processes within the business.
It’s very much like an insurance policy. It has some ongoing cost, but it saves you from the one big cost.
[1] https://www.iso.org/standard/27001
This measure add similar incentive for data breaches.
Personal data needs to be much more of a liability than it currently is for anything to change. Business will respond when the bottom line is affected.
In the case of a university like the head of this thread, it isn’t going to be easy to avoid collecting and retaining data.
for instance, how many companies (including universities) store their own cash on prem? what if we treated PII like cash? limit amount and time kept outside the data "bank" (which would be a third party specialized for security and authenticating access).
They can try:
* various education campaigns
* force users/customers to adopt passkeys or other phishing resistant mfa
* add various alarms and alerts for unusual activity, resulting in lockout
The problem is that even after adopting all of the above, it's still not too hard to breach virtually all companies, and there is massive user opposition to the last two.
Lets say these are paper records, behind a locked door, with a security guard that they check id for it. If someone then breaks in at night time, cuts the cameras and knocks out the security guard and steals a filing cabinet, should that university then be fined 10% of revenue, which could mean the entire university shuts down? We have to remember who is the original criminal here.
But to your point, the article doesn’t define what that means.
Calling "shell company" makes it sound like the University is the shareholder, but that's usually not what's happening IMHO. In general the entities are clearly defined and nothing crosses the client/contractor frame, the university just happens to be the sole client and the contractor will have the uni pay for their whole operation.
guess who holds the bag if capacity needs collapse
Sort of like EULA's a lot of the "value" is incredibly theoretical.
No judge will fall for that. You should have made backups. And you are responsible for the data of your clients.
Courts are run by people, not AI, so judges can easily ignore the corporate entity once these laws are passed.
except you can't in South Korea because PIPA (their data privacy/compliance framework) is as strict if not stricter than GDPR and comes with criminal liability in case you violate consent rules, so you can't just send other people's data to some third party shell company either
why do people always make these completely generic comments as if they've just on the toilet figured out the one simple trick every data framework covered over a decade ago
I'm not familiar with Korean law but that seems a rather high bar. I don't think we'll see many fines actually levied.
(I'm assuming here that 10% is high enough that nobody would call it a cost of doing business - I could be wrong)
Edit: "That'll be $23B. Cash or card?"
Tying the fine to intent or gross negligence doesn't work for me, as a customer doesn't care why, they only care that the harm happened. Doesn't matter to me if you train everyone really well and one guy forgot his training just one time, or if you don't train at all.
I'm thinking:
(The following example is in "American" terms, I assume some other countries have similar ideas as SSN though)
- Name and address or name and phone number leak: $100 per customer affected.
- Email: $50 per customer affected, or $100 if tied to any other data.
- Social Security numbers: $2000 per customer affected
- Unsalted or plaintext passwords: $500 per customer affected.
- Cap is the greater of 200% of annual EBITDA, or 20% of revenue
Money goes to the government to be distributed DIRECTLY (tax-free) to the affected users.
This might bankrupt a couple of companies in particularly bad breaches, while companies are still getting used to it. Good! I hope it does and that business textbooks highlight those disasters, the way they do the Enron collapse.
My goals for this system are for businesses to properly price in the risk of holding (or even momentarily touching) sensitive data. SSNs, for instance should already (in a sane world) be radioactive for any business to even CONSIDER touching. To the extent any business feels the need to collect or hold it, frankly I'd say, think again. Credit reporting agencies are the worst offenders (and under my rules Equifax would already be gone), as they maintain databases with that as primary key, and force all their customers to deal in that key, instead of taking advantage of some 1990s technology like one-way hashing, or better yet, coming up with their own identifiers that could be replaced responsibly in the case of breaches.
10% maximum mean nothing if it’s not enforced, you got to make examples.
Security costs money and as long as there aren't any penalties for negligence management will make the calculation to prioritize increased profitability over securing company data.
So even though this is Korea, it is modern hypocrisy. Companies have to comply to more and more complicated regulation, while those who govern the states get a free pass.
If the Berlin incident remotely had happened to any private company - hell would have been loose.
Berlin reduced the IT budget especially regarding maintenance and security massively over the years. In fact, what came to light - CCC talk as a reference besides others - sounds so embarrassing, that all companies should get a bonus payment whenever they get hacked.
Basing it on revenue is sensible, since the goal is to make it hurt. But that would argue for a higher fraction. But the main thing is to introduce an incentive to take security more seriously.